Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,402 vulnerabilities found (page 1247 of 1617)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| ba0de040-5906-4a67-9306-7e6e65cca78f | < 7.5.1 |
MEDIUM | 4.9 | Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administra… | — | wordfence |
| b972626c-6374-4084-a0e1-1ea4a3062228 | < 2.33 |
MEDIUM | 4.9 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Trave… | — | wordfence |
| b95af878-f324-44ae-a4bf-0c1e994bb3c1 | < 3.1 |
MEDIUM | 4.9 | The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a… | — | wordfence |
| b8440c1d-2a02-42b4-8fc5-42e5a107c0af | < 3.9.8 |
MEDIUM | 4.9 | The SMS Alert β SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… | — | wordfence |
| b82a0f71-29d7-469a-8c69-5ab68d599cb9 | < 2.2.3 |
MEDIUM | 4.9 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2… | — | wordfence |
| b809d705-a08f-45f2-8d4d-bc50ab89cc3a | < 7.0 |
MEDIUM | 4.9 | The SMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.9.12 due to insufficient… | — | wordfence |
| b7850e73-8ffd-46d4-97c6-5343486a31dc | < 1.15.44 |
MEDIUM | 4.9 | The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to gener… | — | wordfence |
| b68a067f-91b0-413a-a164-c8d6a7c45d18 | < 1.5.11 |
MEDIUM | 4.9 | The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to SQL Injection in all versions up … | — | wordfence |
| b6675c48-43d4-4394-a4a3-f753bdaa5c4e | < 1.1.8 |
MEDIUM | 4.9 | The PDF Generator For Fluent Forms β The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site S… | — | wordfence |
| b6364415-da02-4236-b635-d8fbd27faa33 | < 5.8.2 |
MEDIUM | 4.9 | The Simple History plugin for WordPress is vulnerable to sensitive data exposure via Detective Mode due to improper sani… | — | wordfence |
| b5635423-d17a-4f04-a164-64bf141b6bb4 | < 3.43 |
MEDIUM | 4.9 | The IP Blacklist Cloud plugin for WordPress is vulnerable to Directory Traversal in versions before 3.43 via the importC… | — | wordfence |
| b5582e89-83e6-4898-b9fe-09eddeb5f7ae | < 3.7.39 |
MEDIUM | 4.9 | WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploite… | — | wordfence |
| b3fd57f3-f168-4a21-b6cd-f5214f047578 | < 2.4.1 |
MEDIUM | 4.9 | The Infocob CRM Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.4.0. … | — | wordfence |
| b3a58e68-d1f1-4d4f-ac64-bc6cb7dbdbfc | < 2.4.4 |
MEDIUM | 4.9 | The Booking for Appointments and Events Calendar β Amelia plugin for WordPress is vulnerable to SQL Injection via the … | — | wordfence |
| b3523535-6938-4922-8126-8386861ca512 | MEDIUM | 4.9 | The GMAce plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 1.5.2 via the 'gm-… | — | wordfence | |
| b31fcf67-61c7-43b2-a068-136b13965ca0 | MEDIUM | 4.9 | The Contact Form 7 Round Robin Lead Distribution plugin for WordPress is vulnerable to SQL Injection in versions up to, … | — | wordfence | |
| b1978b8f-d207-44e5-8ec0-f2c047192d02 | < 3.10.2 |
MEDIUM | 4.9 | The FunnelKit β Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to SQL Injection in all ver… | — | wordfence |
| b0add190-5f7e-4153-9896-3584773fdd4c | < 2.6.7 |
MEDIUM | 4.9 | The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.6 due to insuffici… | — | wordfence |
| b09d26ac-8f10-458f-8a97-8fdbdff4d833 | < 3.4.4 |
MEDIUM | 4.9 | The Watu Quiz plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.3 due to insuffi… | — | wordfence |
| b07c507e-9fab-426d-998e-ab557d1f1b1a | < 6.18.13 |
MEDIUM | 4.9 | The SeedProd Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.18.12 due to in… | — | wordfence |
| af14ed79-f92d-4573-88ba-d2ef7b2e0a05 | < 8.5.0 |
MEDIUM | 4.9 | The Element Pack Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … | — | wordfence |
| ad2f240b-39b1-4fe9-9e49-1c88d2bfee38 | < 2.0.15 |
MEDIUM | 4.9 | The Check & Log Email plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.14 due t… | — | wordfence |
| ac9c676b-e15b-4052-9d93-e4185a49afe5 | MEDIUM | 4.9 | The Neoforum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insufficie… | — | wordfence | |
| abd6eeac-0a7e-4762-809f-593cd85f303d | < 4.19.2 |
MEDIUM | 4.9 | The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versio… | — | wordfence |
| ab9f69ce-8589-47a8-80b1-6829c5a5bad1 | < 6.4.7 |
MEDIUM | 4.9 | The Auto Affiliate Links plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.4.6… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →